Skip to main content
Outcome: one Verify function with small adapters for net/http, Gin, and Echo. Each reads the bearer key, checks an optional permission query, returns the right status, and puts the verification data on the request.
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
The root key needs api.*.verify_key. Install the SDK with go get github.com/unkeyed/sdks/api/go/v3, then the frameworks you use.

The shared core

auth/auth.go
Reason tells a caller who sent no key that the token is missing, instead of NOT_FOUND. Err is set only when the call to Unkey failed, so the adapters can return 503.

Adapters

Using it

wiring
To forward rate limit state to clients, read res.Data.Ratelimits. Each entry has Limit, Remaining, and Reset (Unix milliseconds) for one checked limit.
  • Go guide for creating keys and the full walk-through.
  • Verifying keys for the fields on V2KeysVerifyKeyResponseData.
Last modified on September 29, 2026